wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CISA 2.7.24

Total questions: 8

Worksheet time: 12mins

Name
Class
Date
1.

When an intrusion into an organization's network is detected, which of the following should be done FIRST?

a)

Contact law enforcement.

b)

Identify nodes that have been compromised.

c)

Block all compromised network nodes.

d)

Notify senior management

2.

Which of the following is an audit reviewer's PRIMARY role with regard to evidence?

a)

Ensuring appropriate statistical sampling methods were used

b)

Ensuring evidence is labeled to show it was obtained from an approved source

c)

Ensuring unauthorized individuals do not tamper with evidence after it has been captured

d)

Ensuring evidence is sufficient to support audit conclusions

3.

Which of the following would be MOST useful to an IS auditor assessing the effectiveness of IT resource planning?

a)

Budget execution status

b)

A capacity analysis of IT operations

c)

A succession plan for key IT personnel

d)

A list of new applications to be implemented

4.

Which of the following MOST effectively minimizes downtime during system conversions?

a)

Phased approach

b)

Parallel run

c)

Direct cutover

d)

Pilot study

5.

Which of the following is the MOST important reason for IS auditors to perform post-implementation reviews for critical IT projects?

a)

To determine whether vendors should be paid for project deliverables

b)

To provide the audit committee with an assessment of project team performance

c)

To provide guidance on the financial return on investment (ROI) of projects

d)

To determine whether the organization's objectives were met as expected

6.

Which of the following is the PRIMARY role of the IS auditor in an organization's information classification process?

a)

Securing information assets in accordance with the classification assigned

b)

Validating that assets are protected according to assigned classification

c)

Ensuring classification levels align with regulatory guidelines

d)

Defining classification levels for information assets within the organization

7.

Management receives information indicating a high level of risk associated with potential flooding near the organization's data center with in the next few years. As a result, a decision has been made to move data center operations to another facility on higher ground. Which approach has been adopted?

a)

Risk reduction

b)

Risk acceptance

c)

Risk transfer

d)

Risk avoidance

8.

After an employee termination, a network account was removed, but the application account remained active. To keep this issue from recurring, which of the following is the BEST recommendation?

a)

Integrate application accounts with network single sign-on.

b)

Perform periodic access reviews.

c)

Retrain system administration staff.

d)

Leverage shared accounts for the application.